WD n900 Need help blocking an IP ( possible Ddos attack )

Hello there everyone,

I’ve bought me a new N900 just a day ago and now the following thing happend, when i connected it everything was just fine but today it crashed for the following reason,

Sun Aug 11 15:58:58 2013 ATT:002[PING-FLOODING][212.142.62.246][eth1]
Sun Aug 11 15:58:58 2013 ATT:002[PING-FLOODING][212.142.62.247][eth1]
Sun Aug 11 15:58:57 2013 ATT:002[PING-FLOODING][212.142.62.242][eth1]
Sun Aug 11 15:58:36 2013 ATT:002[PING-FLOODING][212.142.62.254][eth1]
Sun Aug 11 15:58:36 2013 ATT:002[PING-FLOODING][212.142.62.242][eth1]
Sun Aug 11 15:58:36 2013 ATT:002[PING-FLOODING][212.142.62.246][eth1]
Sun Aug 11 15:58:36 2013 ATT:002[PING-FLOODING][212.142.62.247][eth1]
Sun Aug 11 15:58:36 2013 ATT:002[PING-FLOODING][212.142.62.226][eth1]

Now i have read on the internet that this might be a Ddos attack, for that i want to block these IP adresses. When i came to the Security / firewall tab of the router i got kinda lost since i don’t really understand the things i have to fill in there, the interface looks like this:

Have tried a few things by now but coudn’t get it to work, is there some-one that might help me further with my problem or either got other solutions? It seems i had more of these problems with the previous router aswell but the logfiles of that one were just not good, wasn’t able to see the ping-flooding.

Thank you,

Vungar

Do you have the IPv4 SPI fierwall active, as well as not allowing Ping to your network from WAN?

Hello there,

For the IPv4 SPI firewall turned on and the Allow pint from wan is turned off like shown down here,

 EDIT  ##

Just had another strange thing, it appeared that the internet connection got lost but the icon on the right side of the screen just told me the connection was fine. i coudn’t surf to any website before i restarted my computer.

Thanks,

Vungar

Back when I has DSL, I remember something like this happening. I just can’t remember if it was due to a double NAT or not. Is the DSL modem set as a bridge? If it’s PPPoE, try setting it to bridge mode and let the Router handle PPPoE. Also, set the router to Always Keep Alive, if that’s possible. The router could be reporting common DSL traffic from the modem like a 10 minute lease time from the modem, but due to its frequency, the router interprets it as a threat. Setting the modem as a bridge and the router handling always connected PPPoE, that inadvertent re-leasing from the modem should be stopped.

Just had another set of attacks,

Mon Aug 12 11:12:08 2013 ATT:002[PING-FLOODING][212.142.62.242][eth1]
Mon Aug 12 11:12:08 2013 ATT:002[PING-FLOODING][212.142.62.244][eth1]
Mon Aug 12 11:12:08 2013 ATT:002[PING-FLOODING][212.142.62.247][eth1]
Mon Aug 12 11:11:45 2013 ATT:002[PING-FLOODING][212.142.62.244][eth1]
Mon Aug 12 11:11:45 2013 ATT:002[PING-FLOODING][212.142.62.250][eth1]
Mon Aug 12 11:11:45 2013 ATT:002[PING-FLOODING][212.142.62.254][eth1]
Mon Aug 12 11:11:45 2013 ATT:002[PING-FLOODING][212.142.62.242][eth1]
Mon Aug 12 11:06:59 2013 ATT:002[PING-FLOODING][212.142.62.226][eth1]
Mon Aug 12 11:06:59 2013 ATT:002[PING-FLOODING][212.142.62.242][eth1]
Mon Aug 12 11:06:38 2013 ATT:002[PING-FLOODING][84.116.244.69][eth1]
Mon Aug 12 11:06:38 2013 ATT:002[PING-FLOODING][212.142.62.230][eth1]
Mon Aug 12 11:06:17 2013 ATT:002[PING-FLOODING][212.142.62.244][eth1]
Mon Aug 12 11:06:17 2013 ATT:002[PING-FLOODING][212.142.62.250][eth1]
Mon Aug 12 11:06:17 2013 ATT:002[PING-FLOODING][212.142.62.254][eth1]
Mon Aug 12 11:06:16 2013 ATT:002[PING-FLOODING][212.142.62.226][eth1]
Mon Aug 12 11:06:16 2013 ATT:002[PING-FLOODING][212.142.62.242][eth1]
Mon Aug 12 11:05:55 2013 ATT:002[PING-FLOODING][84.116.244.69][eth1]
Mon Aug 12 11:05:55 2013 ATT:002[PING-FLOODING][212.142.62.230][eth1]
Mon Aug 12 11:05:34 2013 ATT:002[PING-FLOODING][(null)][eth1]
Mon Aug 12 11:05:34 2013 ATT:002[PING-FLOODING][(null)][eth1]
Mon Aug 12 11:05:34 2013 ATT:002[PING-FLOODING][(null)][eth1]
Mon Aug 12 11:05:33 2013 ATT:002[PING-FLOODING][212.142.62.244][eth1]

Will be calling my ISP today for the check on the bridge mode since i can’t get into the modem we have, also do you know if there is an Keep-alive of auto-reconnect function in the Mynet n900?

Thanks in advance,

Vungar